VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25380 CVEsRSS

CVE-2026-15890Medium· 5.3
1w ago

The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized functi…

The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized functi…

▾ Sunlitzephyrproject · zephyrEPSS 0.06%via NVD
CVE-2026-46650Medium· 4.4
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs,…

▾ Sunlitlaurent22 · joplinEPSS 0.29%via NVD
CVE-2026-17054Medium· 5.3
1w ago

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task()

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and …

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-94536Medium· 4.3PoC
1w ago

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can supply arbitrary employeeId values to…

▾ Twilightdromara · lamp-cloudEPSS 0.34%via NVD
CVE-2026-79079High· 7.8PoC
1w ago

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

▾ MidnightRed HatEPSS 0.19%via NVD
CVE-2026-59830Medium· 5.4
1w ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a cra…

▾ Sunlitdiscourse · discourseEPSS 0.29%via NVD
CVE-2026-93340Medium· 6.8
1w ago

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in…

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in…

▾ SunlitGladys Assistant · Gladys AssistantEPSS 0.53%via NVD
CVE-2026-88738High· 8.8PoC
1w ago

Jazzware RT1000 Edge webUI v

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file i…

▾ MidnightEPSS 0.86%via NVD
CVE-2026-94532Medium· 6.5PoC
1w ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensiti…

▾ Twilightdromara · lamp-cloudEPSS 0.44%via NVD
CVE-2026-88756Medium· 5.3
1w ago

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).

▾ SunlitEPSS 0.22%via NVD
CVE-2026-78806Medium· 5.5
1w ago

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component

▾ SunlitEPSS 0.11%via NVD
CVE-2026-94535High· 7.1PoC
1w ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNoti…

▾ Midnightdromara · lamp-cloudEPSS 0.47%via NVD
CVE-2026-94534High· 7.1PoC
1w ago

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodie…

▾ Midnightdromara · lamp-cloudEPSS 0.49%via NVD
CVE-2026-94533Medium· 6.5PoC
1w ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attac…

▾ Twilightdromara · lamp-cloudEPSS 0.44%via NVD
CVE-2026-78847Critical· 9.8PoC
1w ago

An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.

An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.

▾ AbyssalEPSS 0.60%via NVD
CVE-2026-61851Medium· 6.5
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js atte…

▾ Sunlitchartbrew · chartbrewEPSS 0.47%via NVD
CVE-2026-61743Medium· 6.3PoC
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's server/modules/safeRequest.js calls validateOutboundUrl() to resolve and validate …

▾ Twilightchartbrew · chartbrewEPSS 0.40%via NVD
CVE-2026-65980High· 7.9
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's ClickHouse protocol in server/sources/plugins/clickhouse/clickhouse.protocol.js ca…

▾ Twilightchartbrew · chartbrewEPSS 0.66%via NVD
CVE-2026-61852Medium· 5.8PoC
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js inte…

▾ Twilightchartbrew · chartbrewEPSS 0.36%via NVD
CVE-2026-88412Medium· 5.3
1w ago

An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ SunlitEPSS 0.40%via NVD
CVE-2026-88411High· 7.5
1w ago

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

▾ TwilightEPSS 0.49%via NVD
CVE-2026-88410High· 7.1
1w ago

The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

▾ TwilightEPSS 0.32%via NVD
CVE-2026-88409High· 8.8
1w ago

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ TwilightEPSS 0.48%via NVD
CVE-2026-88408Medium· 6.5
1w ago

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-88407High· 7.5
1w ago

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-88406High· 7.5
1w ago

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted i…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-88404Critical· 9.8PoC
1w ago

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

▾ AbyssalEPSS 0.86%via NVD
CVE-2026-88402Critical· 9.8PoC
1w ago

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

▾ AbyssalEPSS 0.47%via NVD
CVE-2026-79919Medium· 6.3
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack he…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.39%via NVD
CVE-2026-79918Medium· 6.3
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.36%via NVD
CVEs tagged “nvd” — page 94 · VulnSea